The web is in the middle of a massive change from non-secure HTTP to the more secure
HTTPS protocol. All web servers use one of these two protocols to get web pages from
the server to your browser. HTTP has serious problems that make it vulnerable to
eavesdropping and content hijacking. HTTPS fixes most of these problems. That's
why EFF, and many like-minded supporters, have been pushing for web sites to adopt
HTTPS by default. As of 2016, about half of all web page visits use HTTPS. This is a
big improvement over the past, but we still have work to do.

We're calling on all web site owners to implement HTTPS by default, and
we're providing the tools to do it.

For many years, web site owners chose to only implement HTTPS for a small number of
pages, like those that accepted passwords or credit card numbers. However, in recent
years, the Internet security community has come to realize that all web pages need
protection. Pages served over HTTP are vulnerable to eavesdropping, content injection,
and cookie stealing, which can be used to take over your online accounts.

What you can do as an individual

Unfortunately, you can only use HTTPS on websites that support it, and there are
still lots of sites that don't. However, a lot of sites partially support
HTTPS— they make HTTPS available but don't send visitors to the HTTPS
version by default.

EFF created and maintains a browser extension, HTTPS Everywhere, that has a list of many
such sites, and will take you to their HTTPS version automatically. We recommend
installing it in all your browsers to make you safer from eavesdropping and content
injection on the sites it lists.

You can also check your favorite sites. When you visit them, does the URL bar at the
top of your browser show "https://"? If not, you should contact the people
who run those sites and demand HTTPS support. Feel free to link them here for a
description of why it's important.

What you can do as a web site owner

We're encouraging everyone who runs a web site to offer HTTPS and redirect
visitors to HTTPS by default. Offering HTTPS has gotten a lot
cheaper in the last 10 years, and today it won't slow down your site or make
it use more server CPU. In fact, offering HTTPS makes it possible for sites to
implement the modern HTTP/2 standard, which can dramatically speed up web browsing
relative to HTTP.

Offering HTTPS requires getting a certificate from a certificate authority. It used
to be expensive and complicated to get a certificate, but a new certificate authority,
Let's Encrypt, offers free certificates to
the public using an API that enables easy automation. Let's Encrypt is a joint
project of EFF, Mozilla, and many other sponsors.

If you manage your web site entirely through a web interface, the easiest approach
is for your hosting provider to integrate Let's Encrypt support as a setting you
can turn on. Many
hosting providers already support Let's Encrypt, and many more add support
all the time.

If you have shell access on your hosting provider, you can use Certbot, a tool developed by EFF. Certbot can get you a
free certificate from Let's Encrypt. It can also automatically configure your
Apache or Nginx server to correctly use that certificate.

What you can do as a hosting
provider

We encourage all hosting providers and CDNs to offer HTTPS by default for their
customers, at no additional cost versus their HTTP services. Many already have, like
Cloudflare, OVH, WordPress.com, and SquareSpace. The Let's Encrypt integration
guide has additional details on how to best implement HTTPS by default. We look
forward to seeing free, automatic HTTPS become the industry standard for web
hosting.

In yet another milestone on the path to encrypting the web, Let’s Encrypt has now issued over 50 million active certificates. Depending on your definition of “website,” this suggests that Let’s Encrypt is protecting between about 23 million and 66 million websites with HTTPS (more on that...

The movement to encrypt the web reached milestone after milestone in 2017. The web is in the middle of a massive change from non-secure HTTP to the more secure, encrypted HTTPS protocol. All web servers use one of these two protocols to get web pages from the server to...

Securely browsing the Internet—even when you know what you’re doing—is tough. That’s partly why, nearly seven years ago, EFF worked together with The Tor Project to develop a privacy tool called HTTPS Everywhere, which automatically provides users with secure, encrypted connections to websites when available.
While HTTPS Everywhere can be...

For years, EFF has commended companies who make cloud applications that encrypt data in transit. But soon, the new gold standard for cloud application encryption will be the cloud provider never having access to the user’s data—not even while performing computations on it. Microsoft has become the first major cloud...

"The laws of mathematics are very commendable but the only law that applies in Australia is the law of Australia", said Australian Prime Minister Malcolm Turnbull today. He has been rightly mocked for this nonsense claim, that foreshadows moves to require online messaging providers to provide law enforcement with...